← Back to browse · API

CVE-2026-33937

Severity
CRITICAL
CVSS
9.8
EPSS
0.02254
Risk score
39.99
CISA KEV
No
PoC
Yes
Published
2026-03-27
Modified
2026-07-15
First seen
2026-08-07
Aliases
EUVD-2026-16848, GHSA-2W6W-674Q-4C4Q
Products
handlebars-lang:handlebars.js 4.0.0, < 4.7.9
Sources
github 7dba843b2f112b549df37ac5|CVE-2026-33937
packetstorm 8437413a500c2ad541f5075b|CVE-2026-33937
euvd EUVD-2026-16848
github b246612e8d2ccf6f9b4d0df2|CVE-2026-33937
packetstorm c0a10f814416d3b26c21627f|CVE-2026-33937

Description

Handlebars provides the power necessary to let users build semantic templates. In versions 4.0.0 through 4.7.8, `Handlebars.compile()` accepts a pre-parsed AST object in addition to a template string. The `value` field of a `NumberLiteral` AST node is emitted directly into the generated JavaScript without quoting or sanitization. An attacker who can supply a crafted AST to `compile()` can therefore inject and execute arbitrary JavaScript, leading to Remote Code Execution on the server. Version 4.7.9 fixes the issue. Some workarounds are available. Validate input type before calling `Handlebars.compile()`; ensure the argument is always a `string`, never a plain object or JSON-deserialized value. Use the Handlebars runtime-only build (`handlebars/runtime`) on the server if templates are pre-compiled at build time; `compile()` will be unavailable.

References